What Are Data Breach Notification Requirements for RIAs?
Following the 2024 Regulation S-P amendments, SEC-registered advisers with an incident affecting sensitive customer information generally must notify affected individuals within 30 days of discovering unauthorized access, unless the firm determines the information hasn’t been or is unlikely to be misused. State-registered advisers may also be subject to state data breach notification laws, which vary considerably in their triggers and timelines — some apply based on the residency of affected individuals regardless of where the firm is located.
Firms need an incident response plan that spells out the investigation process, the notification decision-making chain, and template client communications prepared in advance rather than drafted under pressure during an actual incident.